Vulnerability index

Browse CVEs

1,246 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
Portainer CRITICAL 9.8
CVE-2018-19466

A vulnerability was found in Portainer before 1.20.0. Portainer stores LDAP credentials, corresponding to a master password, in cleartext and allows …

Fix: 1.20.0+
Fix from $2,300 2019-03-27
Ovirt Engine HIGH 8.8
CVE-2017-7510

In ovirt-engine 4.1, if a host was provisioned with cloud-init, the root password could be revealed through the REST interface.

Mitigation only
Fix from $1,950 2019-03-25
Netbackup Appliance HIGH 7.2
CVE-2019-9867

An issue was discovered in the Web Console in Veritas NetBackup Appliance through 3.1.2. The proxy server password is displayed to an administrator.

Fix: after 3.1.2
Fix from $1,950 2019-03-21
Netbackup Appliance HIGH 7.2
CVE-2019-9868

An issue was discovered in the Web Console in Veritas NetBackup Appliance through 3.1.2. The SMTP password is displayed to an administrator.

Fix: after 3.1.2
Fix from $1,950 2019-03-21
Portier CRITICAL 9.8
CVE-2019-5723

An issue was discovered in portier vision 4.4.4.2 and 4.4.4.6. Passwords are stored using reversible encryption rather than as a hash value, and the …

No fix yet
Fix from $2,300 2019-03-21
Passport HIGH 7.8
CVE-2018-17500

Envoy Passport for Android and Envoy Passport for iPhone could allow a local attacker to obtain sensitive information, caused by the storing of hardc…

Mitigation only
Fix from $1,950 2019-03-21
Repository Connector HIGH 7.8
CVE-2019-1003038

An insufficiently protected credentials vulnerability exists in Jenkins Repository Connector Plugin 1.2.4 and earlier in src/main/java/org/jvnet/huds…

Fix: after 1.2.4
Fix from $1,950 2019-03-08
Appdynamics HIGH 8.8
CVE-2019-1003039

An insufficiently protected credentials vulnerability exists in JenkinsAppDynamics Dashboard Plugin 1.0.14 and earlier in src/main/java/nl/codecentri…

Fix: after 1.0.14
Fix from $1,950 2019-03-08
Container Runtime HIGH 8.8
CVE-2019-3780

Cloud Foundry Container Runtime, versions prior to 0.28.0, deploys K8s worker nodes that contains a configuration file with IAAS credentials. A malic…

Fix: 0.28.0+
Fix from $1,950 2019-03-08
Rational Clearcase CRITICAL 9.8
CVE-2019-4059

IBM Rational ClearCase 1.0.0.0 GIT connector does not sufficiently protect the document database password. An attacker could obtain the password and …

Fix: 9.0.1.5+
Fix from $2,300 2019-02-15
Credhub Cli HIGH 7.8
CVE-2019-3782

Cloud Foundry CredHub CLI, versions prior to 2.2.1, inadvertently writes authentication credentials provided via environment variables to its persist…

Fix: 2.2.1+
Fix from $1,950 2019-02-13
Pr100088 Modbus Gateway Firmware HIGH 7.2
CVE-2019-6549

An attacker could retrieve plain-text credentials stored in a XML file on PR100088 Modbus gateway versions prior to Release R02 (or Software Version …

Mitigation only
Fix from $1,950 2019-02-12
Ubuntu Linux HIGH 7.8
CVE-2018-20781

In pam/gkr-pam-module.c in GNOME Keyring before 3.27.2, the user's password is kept in a session-child process spawned from the LightDM daemon. This …

Fix: 3.27.2+
Fix from $1,950 2019-02-12
Xperience HIGH 7.2
CVE-2019-6242

Kentico v10.0.42 allows Global Administrators to read the cleartext SMTP Password by navigating to the SMTP configuration page. NOTE: the vendor cons…

No fix yet
Fix from $1,950 2019-02-08
Teampass CRITICAL 9.8
CVE-2019-1000001

TeamPass version 2.1.27 and earlier contains a Storing Passwords in a Recoverable Format vulnerability in Shared password vaults that can result in a…

Fix: after 2.1.27.0
Fix from $2,300 2019-02-04
Artica Proxy HIGH 7.2
CVE-2019-7300

Artica Proxy 3.06.200056 allows remote attackers to execute arbitrary commands as root by reading the ressources/settings.inc ldap_admin and ldap_pas…

No fix yet
Fix from $1,950 2019-02-01
Unified Communications Manager HIGH 8.8
CVE-2018-0474

A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an authenticated, remote attacker to view d…

Mitigation only
Fix from $1,950 2019-01-10
Crowd2 HIGH 7.8
CVE-2018-1000423

An insufficiently protected credentials vulnerability exists in Jenkins Crowd 2 Integration Plugin 2.0.0 and earlier in CrowdSecurityRealm.java, Crow…

Fix: after 2.0.0
Fix from $1,950 2019-01-09
Artifactory HIGH 7.8
CVE-2018-1000424

An insufficiently protected credentials vulnerability exists in Jenkins Artifactory Plugin 2.16.1 and earlier in ArtifactoryBuilder.java, Credentials…

Fix: after 2.16.1
Fix from $1,950 2019-01-09
Sonarqube Scanner HIGH 7.8
CVE-2018-1000425

An insufficiently protected credentials vulnerability exists in Jenkins SonarQube Scanner Plugin 2.8 and earlier in SonarInstallation.java that allow…

Fix: after 2.8
Fix from $1,950 2019-01-09
V2i Hub CRITICAL 9.8
CVE-2018-1000627

Battelle V2I Hub 2.5.1 could allow a remote attacker to obtain sensitive information, caused by the failure to restrict access to the API key file. A…

Mitigation only
Fix from $2,300 2018-12-28
Univerge Sv9100 Webpro Firmware CRITICAL 9.8
CVE-2018-11742EPSS 14%

NEC Univerge Sv9100 WebPro 6.00.00 devices have Cleartext Password Storage in the Web UI.

No fix yet
Fix from $2,300 2018-12-26
Tc7110.ar Firmware CRITICAL 9.8
CVE-2018-20438

Technicolor TC7110.AR STD3.38.03 devices allow remote attackers to discover Wi-Fi credentials via iso.3.6.1.4.1.2863.205.10.1.30.4.1.14.1.3.32 and is…

No fix yet
Fix from $2,300 2018-12-25
Dpc3928sl Firmware CRITICAL 9.8
CVE-2018-20439

Technicolor DPC3928SL D3928SL-PSIP-13-A010-c3420r55105-170214a devices allow remote attackers to discover Wi-Fi credentials via iso.3.6.1.4.1.4413.2.…

Mitigation only
Fix from $2,300 2018-12-25
Cwa0101 Firmware CRITICAL 9.8
CVE-2018-20440

Technicolor CWA0101 CWA0101E-A23E-c7000r5712-170315-SKC devices allow remote attackers to discover Wi-Fi credentials via iso.3.6.1.4.1.4413.2.2.2.1.5…

No fix yet
Fix from $2,300 2018-12-25
Tc7200.th2v2 Firmware CRITICAL 9.8
CVE-2018-20441

Technicolor TC7200.TH2v2 SC05.00.22 devices allow remote attackers to discover Wi-Fi credentials via iso.3.6.1.4.1.2863.205.10.1.30.4.1.14.1.3.32 and…

No fix yet
Fix from $2,300 2018-12-25
Tc7110.b Firmware CRITICAL 9.8
CVE-2018-20442

Technicolor TC7110.B STC8.62.02 devices allow remote attackers to discover Wi-Fi credentials via iso.3.6.1.4.1.2863.205.10.1.30.4.1.14.1.3.32 and iso…

No fix yet
Fix from $2,300 2018-12-25
Tc7200.d1i Firmware CRITICAL 9.8
CVE-2018-20443

Technicolor TC7200.d1I TC7200.d1IE-N23E-c7000r5712-170406-HAT devices allow remote attackers to discover Wi-Fi credentials via iso.3.6.1.4.1.4413.2.2…

No fix yet
Fix from $2,300 2018-12-25
Cga0111 Firmware CRITICAL 9.8
CVE-2018-20444

Technicolor CGA0111 CGA0111E-ES-13-E23E-c8000r5712-170217-0829-TRU devices allow remote attackers to discover Wi-Fi credentials via iso.3.6.1.4.1.441…

Mitigation only
Fix from $2,300 2018-12-25
Dcm 604 Firmware CRITICAL 9.8
CVE-2018-20445

D-Link DCM-604 DCM604_C1_ViaCabo_1.04_20130606 and DCM-704 EU_DCM-704_1.10 devices allow remote attackers to discover Wi-Fi credentials via iso.3.6.1…

No fix yet
Fix from $2,300 2018-12-25